Candidate: CVE-2011-4320 PublicDate: 2012-02-18 00:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4320 https://support.process-one.net/browse/EJAB-1498 Description: The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_ejabberd: upstream_ejabberd: released (2.1.9-1) hardy_ejabberd: ignored (reached end-of-life) lucid_ejabberd: ignored (reached end-of-life) maverick_ejabberd: ignored (reached end-of-life) natty_ejabberd: ignored (reached end-of-life) oneiric_ejabberd: ignored (reached end-of-life) precise_ejabberd: not-affected (2.1.9-1) quantal_ejabberd: not-affected (2.1.9-1) raring_ejabberd: not-affected (2.1.9-1) saucy_ejabberd: not-affected (2.1.9-1) devel_ejabberd: not-affected (2.1.9-1)